There is no single global AI law. There are four kinds of rule, and most organisations meet at least two of them.
1. The EU: one big statute
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It entered into force on 1 August 2024 and applies in stages. Bans on "unacceptable" practices and the AI literacy duty applied from 2 February 2025. Duties for general-purpose AI models applied from 2 August 2025. Transparency duties for chatbots and synthetic content applied from 2 August 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the high-risk obligations back: 2 December 2027 for stand-alone high-risk uses such as hiring and credit, and 2 August 2028 for AI built into regulated products.
The Act reaches beyond Europe. If your system's output is used in the EU, or you sell to EU customers, it can apply to you wherever you sit. Fines under Article 99 go up to EUR 35 million or 7 percent of worldwide turnover for prohibited practices.
2. The United States: a patchwork
There is no federal AI statute. Instead you have three layers:
- Federal agencies applying old laws to new tools. The FTC uses its unfair-and-deceptive-practices power against misleading AI claims and reckless deployments. The EEOC applies Title VII, the ADEA and the ADA to hiring tools.
- State and city laws. Colorado's SB 26-189 (obligations from 1 January 2027) governs automated decision-making in "consequential decisions". Texas's TRAIGA (in force 1 January 2026) bans specific harmful uses and gives the Attorney General enforcement power. Illinois HB 3773 (in force 1 January 2026) treats discriminatory AI in employment as a civil-rights violation and requires notice. California's AB 2013 (1 January 2026) requires training-data summaries for generative AI, and SB 942 (operative 2 August 2026) requires detection tools and content labels from large generative providers. New York City's Local Law 144 has required bias audits of hiring tools since July 2023. Utah adds generative-AI disclosure duties and New York's RAISE Act targets frontier-model developers.
- Federal pushback. Executive Order 14365 (11 December 2025) set up a Department of Justice task force to challenge state AI laws the administration considers burdensome and directed agencies to propose a national framework. Until Congress acts, state laws remain in force, but expect litigation and changes.
3. Canada: privacy law does the work
Canada's proposed federal AI statute (AIDA) died in January 2025 and the government has said it will not return. What applies instead is PIPEDA (federal private-sector privacy law; a replacement, Bill C-36, was tabled on 15 June 2026), Quebec's Law 25 (which since September 2023 requires notice of decisions made exclusively by automated processing), Ontario's job-posting rule (since 1 January 2026, employers with 25 or more staff must say if AI screens applicants), and, for federal institutions, the Treasury Board's Directive on Automated Decision-Making and its Guide on the use of generative AI.
4. Standards: voluntary, but they set the bar
The NIST AI Risk Management Framework (2023, with a generative-AI profile in 2024) and ISO/IEC 42001:2023 are not laws. But regulators cite them, contracts require them, and Texas offers a defence to organisations that follow a recognised framework such as NIST's.
How to use the map
Pick the jurisdictions where you have users, staff or customers. Then ask which role you play (builder or deployer) and which use cases you run. The Academy's screener does this for you and lists the laws that plausibly apply.